Skip to Content
CIGFARO Legal & Privacy

Terms & Conditions Privacy & POPIA Notice

These terms govern the use of CIGFARO's website, membership services, applications, registrations, events, training, payments and related digital services.

Please read these terms carefully.

By using the CIGFARO website, creating an account, submitting a membership application, registering for an event or training programme, making a payment or otherwise providing information to CIGFARO, you acknowledge these Terms and Conditions and the processing of personal information described in this notice, subject to applicable law.

Terms of Use

Terms governing CIGFARO services and information

References to “CIGFARO”, “we”, “us” or “our” mean the Chartered Institute of Government Finance, Audit & Risk Officers.

References to “you”, “member”, “applicant”, “delegate” or “user” include any person using the website, applying for membership, attending an event, enrolling for training or interacting with CIGFARO's digital services.

01

Website Use & General Terms

The CIGFARO website and related portals are provided for informational, professional, membership, educational, registration and transactional purposes.

  • You must use the website lawfully and may not attempt to interfere with, damage or gain unauthorised access to the website, systems, accounts or data.
  • Information submitted through CIGFARO platforms must, to the best of your knowledge, be accurate, complete and current.
  • You remain responsible for maintaining the confidentiality of your account credentials.
  • You must notify CIGFARO if you believe that your account or personal information has been accessed without authorisation.
  • CIGFARO may suspend or restrict access where there is suspected misuse, fraud, unlawful activity or a material breach of these terms.
02

Membership Applications & Professional Designations

Application Information

Applicants may be required to provide personal, professional, academic, employment and supporting documentation so that CIGFARO can assess membership and designation eligibility.

Verification

CIGFARO may verify qualifications, identity, employment, professional experience and supporting documents where reasonably required to assess an application.

Membership decisions

Submission of an application does not automatically result in membership, professional designation or approval. Applications remain subject to the applicable eligibility requirements, supporting documentation, assessment procedures, fees and CIGFARO approval processes.

  • Applicants are responsible for ensuring information supplied is accurate and not misleading.
  • CIGFARO may request additional information or supporting evidence.
  • Professional designations may be subject to qualification, experience, competency and continuing professional development requirements.
  • Membership may be subject to CIGFARO's Constitution, Code of Conduct, professional standards, disciplinary processes and other applicable policies.
  • Membership fees and requirements may be amended from time to time.
03

Fees, Payments & Transactions

Membership fees, event registrations, training fees, publications and other chargeable services are payable in accordance with the fees displayed or communicated by CIGFARO at the relevant time.

  • Fees may be subject to VAT or other applicable taxes.
  • A transaction is subject to successful payment, verification and, where applicable, CIGFARO approval.
  • Incorrectly quoted or displayed pricing may be corrected where an obvious error has occurred.
  • Membership or service access may be suspended where applicable fees remain unpaid.
  • CIGFARO may use external banks, payment gateways, payment acquirers and payment service providers to process transactions.
Payment information

Payment details may be collected or processed directly by an authorised payment service provider. Depending on the payment method used, CIGFARO may receive transaction references, payment status, payer details and related transaction information rather than full payment-card credentials.

04

Conferences, Seminars & Indabas — Cancellation

Cancellations must be submitted in writing. The following cancellation terms reflect CIGFARO's Conference, Seminar and Indaba cancellation policy.

Up to 45 Days Cancellation Without Penalty

Written cancellation requests received up to and including 45 days before the start of the conference may be cancelled without penalty.

Up to 21 Days Credit Voucher

Due to financial obligations incurred by CIGFARO, written requests received up to and including 21 days prior to the event may receive a credit voucher less 50% of the registration fee.

Less Than 21 Days No Refund or Credit

No refund or credit will be issued for cancellation requests received less than 21 days before the event.

Delegate replacement

Where a registered delegate can no longer attend, another person may attend in the registered delegate's place, subject to CIGFARO being notified.

Where an event-specific registration form, invitation, quotation or agreement provides additional or updated cancellation conditions, those event-specific conditions may apply.

05

Protection of Personal Information — POPIA

How CIGFARO processes your personal information

CIGFARO processes personal information in accordance with applicable South African privacy and data-protection laws, including the Protection of Personal Information Act, 4 of 2013 (“POPIA”).

Personal information will be processed lawfully and reasonably and, where applicable, for a specific, explicitly defined and legitimate purpose connected to CIGFARO's activities.

  • Personal information should be adequate, relevant and not excessive for the purpose for which it is processed.
  • CIGFARO will take reasonably practicable steps to maintain the quality and accuracy of information.
  • Appropriate safeguards will be applied to protect the confidentiality and integrity of personal information.
  • Information will not be retained for longer than necessary unless retention is required or permitted by law, contractual obligations, professional-body requirements or legitimate record-keeping purposes.
06

Information We May Collect

Identity & Contact Information

Name, surname, identity or passport information, contact numbers, email addresses, addresses and other identifying information.

Professional Information

Qualifications, certifications, employment details, work experience, CVs, designations, CPD records and professional supporting documents.

Transaction Information

Payment references, invoices, membership fees, transaction status, event registrations, purchases and accounting-related records.

Website & Technical Information

Login information, browser and device information, website activity, IP address, cookies, audit records and information needed for website security.

07

Why We Process Personal Information

  • Processing and assessing membership applications.
  • Verifying eligibility for membership and professional designations.
  • Maintaining membership and professional records.
  • Managing CPD, training, certification and development activities.
  • Managing conferences, seminars, workshops, Indabas, meetings and other events.
  • Processing payments, invoices, refunds and accounting records.
  • Communicating with members, applicants, delegates, stakeholders and service providers.
  • Providing member portals, certificates, resources, publications and digital services.
  • Meeting statutory, regulatory, tax, accounting, governance and professional-body obligations.
  • Preventing fraud, misuse, security incidents and unauthorised access.
  • Conducting legitimate administrative, operational and governance activities.
  • Sending newsletters, event notices or marketing communications where permitted by law.
08

Third Parties, Operators & Service Providers

CIGFARO may use trusted third parties or operators to provide services that are necessary for its operations. Personal information may be disclosed to such parties only where reasonably required and subject to applicable legal and contractual safeguards.

These parties may include:

  • Banks, payment gateways, payment processors and payment acquirers.
  • Website, hosting, cloud and information technology providers.
  • Odoo and relevant Odoo infrastructure or service providers.
  • Email, SMS, WhatsApp and communications providers.
  • Event venues, conference organisers and event-service providers where necessary for a registration.
  • Training providers, assessors, accreditation bodies and professional partners where applicable.
  • Accounting, audit, legal, governance and professional advisers.
  • Public authorities, regulators or law-enforcement agencies where disclosure is required or permitted by law.
Service providers do not become owners of your data.

Where a third party acts as an operator or processor on CIGFARO's behalf, CIGFARO will seek to ensure that appropriate confidentiality, security and data-processing obligations apply to the services provided.

09

Cross-Border Processing & Cloud Services

Certain technology, cloud, email, payment, communications or support providers may process or store information outside South Africa.

Where personal information is transferred across borders, CIGFARO will seek to ensure that the transfer is handled in accordance with POPIA and that appropriate safeguards, contractual protections or other lawful mechanisms apply.

10

Odoo Platform & Information Security

Technology safeguards

CIGFARO uses technology platforms, including Odoo, to support website, membership, communication, accounting and operational processes.

Odoo publicly states that its security framework includes measures designed to protect customer data and systems. Depending on the hosting and services used, these measures may include:

Encryption

Encryption is used to protect data during transmission and for cloud-hosted customer data at rest.

Access Controls

Role-based permissions, user groups, record rules and authentication controls can be used to limit access to authorised users.

Backups

Odoo cloud services provide backup and resilience mechanisms intended to reduce the risk of data loss.

Network Security

Network protection, firewalls, intrusion-prevention controls and DDoS mitigation form part of Odoo's cloud-security measures.

Secure Authentication

Secure password hashing and supported external authentication mechanisms can assist with protecting account access.

Security Standards

Odoo reports certification of its Information Security Management System to ISO/IEC 27001:2022.

Important clarification regarding ISO certification

Odoo's ISO/IEC 27001 certification and the certifications of its hosting infrastructure relate to Odoo and the applicable certified environments. They should not be interpreted as confirmation that CIGFARO itself is independently ISO/IEC 27001 certified unless CIGFARO has separately obtained such certification.

Payment-card security

Where payment cards are processed through supported Odoo payment integrations, payment information may be transmitted directly to the applicable payment provider or acquirer. The specific payment provider's own terms, privacy notice and security practices may also apply.

CIGFARO operational safeguards

CIGFARO will seek to apply appropriate administrative, organisational and technical safeguards appropriate to the nature of the information being processed. These may include restricted system access, permissions management, password controls, staff confidentiality obligations, access reviews, backups, security updates and incident management processes.

11

Information Retention

CIGFARO may retain records for as long as reasonably necessary for the purposes for which they were collected, or as required by law, regulation, accounting standards, governance requirements, contractual obligations, professional-body requirements or legitimate record-keeping needs.

Records may include membership applications, qualification documentation, membership history, CPD records, financial records, invoices, event records, communications, certificates and compliance documentation.

When information is no longer required and CIGFARO is not legally entitled or required to retain it, reasonable steps may be taken to delete, destroy, anonymise or otherwise render the information irrecoverable.

12

Your Personal Information Rights

Subject to POPIA and other applicable laws, you may have rights relating to personal information held by CIGFARO.

  • Request confirmation as to whether CIGFARO holds personal information about you.
  • Request access to personal information, subject to applicable legal requirements.
  • Request correction or updating of inaccurate or incomplete information.
  • Request deletion or destruction where legally appropriate.
  • Object to certain processing where POPIA permits an objection.
  • Withdraw consent where processing is based on consent, without affecting processing lawfully undertaken before the withdrawal.
  • Object to direct marketing or unsubscribe from marketing communications.
  • Lodge a complaint with the Information Regulator where you believe your personal information has been processed unlawfully.
13

Communications & Direct Marketing

CIGFARO may communicate with members and applicants about membership administration, payments, CPD requirements, events, training, governance matters, publications, professional updates and other service-related matters.

Marketing and promotional communications will be managed in accordance with applicable law. Where required, recipients will be given an appropriate opportunity to consent, object or unsubscribe.

Service-related or legally required communications may continue even where a person has unsubscribed from promotional communications.

14

Cookies & Website Analytics

The CIGFARO website may use cookies and similar technologies that are necessary for website operation, authentication, security, preferences, analytics and functionality.

Where non-essential tracking or marketing technologies require consent under applicable law, appropriate consent mechanisms should be used.

15

Intellectual Property

Unless otherwise indicated, CIGFARO website content, branding, publications, training materials, graphics, documents, professional resources and other materials are owned by or licensed to CIGFARO and may be protected by copyright, trademark and other intellectual-property laws.

Material may not be copied, republished, commercially distributed, altered or presented as another party's work without the required permission, except where permitted by law or expressly authorised.

16

External Links & Third-Party Services

The website may contain links to third-party websites, payment services, event platforms, professional resources or external service providers.

CIGFARO does not control every external website or service and cannot be responsible for the content, availability, privacy practices or security of independent third-party platforms. Users should review the applicable third party's terms and privacy notice.

17

Information, Availability & Liability

CIGFARO aims to keep website information accurate and current, but information may be updated, corrected or changed from time to time.

Website information is generally provided for professional and informational purposes and should not automatically be treated as legal, tax, financial or other professional advice applicable to a user's specific circumstances.

Nothing in these terms excludes or limits liability where such exclusion or limitation is prohibited by applicable South African law.

18

Changes to These Terms

CIGFARO may amend these Terms and Conditions, Privacy Notice or related policies from time to time to reflect changes in legislation, services, technology, operational practices or governance requirements.

The updated version will take effect when published or on another date expressly stated by CIGFARO.

19

Governing Law

These terms are governed by the laws of the Republic of South Africa. Any dispute will be dealt with in accordance with applicable South African law and the jurisdiction of the competent South African courts, subject to any applicable dispute-resolution process.

Questions & Privacy Requests

Contact CIGFARO

If you have questions about these terms, your membership, the processing of your personal information or a privacy-related request, please contact CIGFARO.

STANDARD TERMS AND CONDITIONS OF SALE

You should update this document to reflect your T&C.

Below text serves as a suggestion and doesn’t engage Odoo S.A. responsibility.

  1. The client explicitly waives its own standard terms and conditions, even if these were drawn up after these standard terms and conditions of sale. In order to be valid, any derogation must be expressly agreed to in advance in writing.
  2. Our invoices are payable within 21 working days, unless another payment timeframe is indicated on either the invoice or the order. In the event of non-payment by the due date, My Company reserves the right to request a fixed interest payment amounting to 10% of the sum remaining due. My Company will be authorized to suspend any provision of services without prior warning in the event of late payment.
  3. If a payment is still outstanding more than sixty (60) days after the due payment date, My Company reserves the right to call on the services of a debt recovery company. All legal expenses will be payable by the client.
  4. Certain countries apply withholding at source on the amount of invoices, in accordance with their internal legislation. Any withholding at source will be paid by the client to the tax authorities. Under no circumstances can My Company become involved in costs related to a country's legislation. The amount of the invoice will therefore be due to My Company in its entirety and does not include any costs relating to the legislation of the country in which the client is located.
  5. My Company undertakes to do its best to supply performant services in due time in accordance with the agreed timeframes. However, none of its obligations can be considered as being an obligation to achieve results. My Company cannot under any circumstances, be required by the client to appear as a third party in the context of any claim for damages filed against the client by an end consumer.
  6. In order for it to be admissible, My Company must be notified of any claim by means of a letter sent by recorded delivery to its registered office within 8 days of the delivery of the goods or the provision of the services.
  7. All our contractual relations will be governed exclusively by United States law.
Chat with CIGFARO